<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
    <atom:link href="https://docs.invicti.com/ip/release-notes/Invicti-Platform-on-demand/rss.xml" rel="self" type="application/rss+xml" />
        <title>Invicti Release Notes – Invicti Platform on-demand</title>
        <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes</link>
        <description>New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.</description>
        <lastBuildDate>Fri, 13 Mar 2026 11:33:01 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <language>en</language>
        <copyright>Copyright © 2026 Invicti</copyright>
        <item>
            <title><![CDATA[Release 20260219]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20260219</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20260219</guid>
            <pubDate>Fri, 13 Mar 2026 11:33:01 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<p><em>Release date: 19 February 2026</em></p>
<h4>Improvements</h4>
<ul>
<li>Added the ability to assign tags to scans for better organization and filtering (<a href="tags">Read more</a>)</li>
<li>DAST Scan schedules are no longer shown in the DAST scans page. These are shown in the DAST scheduled scans</li>
<li>Docker image of internal scanning agent now supports ARM64 architecture</li>
<li>Added support for MSSP licensing business logic</li>
<li>Updated DAST engine to handle examples for $ref&#39;d schemas in OpenAPI</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20260205]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20260205</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20260205</guid>
            <pubDate>Fri, 13 Mar 2026 11:33:01 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<p><em>Release date: 5 February 2026</em></p>
<h4>New features</h4>
<ul>
<li>Implemented a feature that allows users to override the severity of vulnerabilities detected in DAST scans (Read more on <a href="change-severity-level">individual vulnerability&#39;s</a> and <a href="severity-overrides">global severity</a> changes)</li>
<li>Implemented screenshot capture during DAST scans to improve visibility of the scanning process and authentication failures (<a href="review-scan-results#scan-summary">Read more</a>)</li>
<li>Compliance classification information is now included in vulnerability details to support regulatory alignment and audit readiness (<a href="view-vulnerability-details#vulnerability-tab">Read more</a>)</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>The platform has been upgraded to Node.js 20.x</li>
<li>AI-powered features are now enabled by default for new accounts. Account owners retain the ability to turn off these features during account creation (<a href="enable-ai-features">Read more</a>)</li>
<li>Scanning agent IP addresses are now visible, improving transparency</li>
<li>Sorting by status on the DAST scans page now automatically uses the scan date as a secondary sort to provide more accurate results</li>
<li>Scheduled scans can now be assigned custom names to improve identification (Read more on <a href="scheduled-future-scan#steps-to-schedule-a-future-scan">scheduled scans</a> and <a href="recurring-scan#steps-to-schedule-a-recurring-scan">recurring scans</a>)</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Resolved an issue where rediscovered vulnerabilities weren&#39;t included in scan and target reports</li>
<li>Fixed an issue where the Download Logs option wasn&#39;t available for aborted scans</li>
<li>Resolved an issue that caused unexpected errors related to missing scan creator information</li>
<li>Corrected an issue where updated threat levels weren&#39;t immediately reflected in the UI after severity changes</li>
<li>Fixed an issue that prevented reports being generated</li>
<li>Resolved an issue where API specifications and related scans weren&#39;t displayed correctly for certain targets</li>
<li>Fixed an issue where Issue URLs weren&#39;t visible within the Vulnerability tab</li>
<li>Resolved an issue causing scans to fail when LSR restrictions were used together with imported files</li>
<li>Fixed an OAuth API validation issue</li>
<li>Resolved a limitation that prevented successful uploads of larger CSV files</li>
<li>Added clearer messaging about maximum file size limits for API source uploads (<a href="add-new-api-source#add-a-new-api-source-from-a-file">Read more</a>)</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20260122]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20260122</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20260122</guid>
            <pubDate>Fri, 13 Mar 2026 11:33:01 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<p><em>Release date: 22 January 2026</em></p>
<h4>Improvements</h4>
<ul>
<li>Added functionality to store a snapshot of target configuration for each scan</li>
<li>Internal scanning agent now support proxy when connecting back to the platform</li>
<li>Improved user messaging to clearly indicate when a scan is automatically aborted after being paused for seven days</li>
<li>Implemented custom URL rewrite rules for DAST scans on larger sites to improve scan efficiency</li>
<li>Introduced safeguards to automatically pause recurring scans after five consecutive failures</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Resolved an issue to improve scheduled scan stability</li>
<li>Corrected an issue with incorrect links in Runtime SCA Findings</li>
<li>Fixed a problem that prevented the Scan Detail page from loading correctly</li>
<li>Optimized internal scanner request handling to reduce excessive request volume</li>
<li>Upgraded the urllib3 library</li>
<li>Removed TRACK and DEBUG from Restricted HTTP methods in the UI</li>
<li>Resolved an issue where false positives and ignored vulnerabilities were still appearing in reports</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20260108]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20260108</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20260108</guid>
            <pubDate>Fri, 13 Mar 2026 11:33:01 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<p><em>Release date: 8 January 2026</em></p>
<h4>New features</h4>
<ul>
<li>Added support for automatic user provisioning during IdP-initiated SAML SSO login</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Enhanced the scanning engine to support non-standard OAuth authorization flows</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Resolved an issue in notifications</li>
<li>Fixed an issue that limited the Exemptions list to display only the first 50 users</li>
<li>Resolved a problem where long Scan Profile description caused the profile list to fail loading</li>
<li>Fixed an issue that prevented users from creating scan schedules when an end date was specified</li>
<li>Resolved an issue related to notifications not displaying correctly during scans with allowed hosts</li>
<li>Fixed a synchronization issue to ensure updates to target agents are correctly communicated</li>
<li>Resolved an issue that allowed duplicate file imports</li>
</ul>
<hr>
<h2>2025</h2>
<p>This section summarizes all releases, features, improvements, and fixes for 2025 as they&#39;re added.</p>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20251218]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20251218</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20251218</guid>
            <pubDate>Fri, 13 Mar 2026 11:33:01 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<p><em>Release date: 18 December 2025</em></p>
<h4>New features</h4>
<ul>
<li>Added CircleCI integration (<a href="/continuous-integration-overview">Read more</a>)</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>In Automations, the &quot;Report generated&quot; event is now an action within the &quot;Scan completed&quot; event (<a href="/new-automation#example-1-email-a-report-when-scan-completes">Read more</a>)</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue where a vulnerability could be sent to multiple issue trackers (<a href="/issue-trackers-overview">Read more here</a> <a href="/send-vulnerability-to-issue-tracker">and here</a>)</li>
<li>Fixed an issue where editing an existing Jira integration caused authentication issues (<a href="/jira-basic-token#troubleshooting-authentication-issues">Read more</a>)</li>
<li>Fixed an issue where assignee was removed when editing vulnerability details</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20251204]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20251204</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20251204</guid>
            <pubDate>Thu, 04 Dec 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Improved API Insights dashboard to respect user access restrictions, preventing users from viewing results for targets they don&#39;t have permission to access. Only users who have access to all targets can view the dashboard (<a href="/api-insights-dashboard">Read more</a>)</li>
<li>Users can now add bulk comments and tags to vulnerabilites (<a href="/add-comments-tags-vulnerabilities">Read more</a>)</li>
<li>Enabled users to re-register multiple times using the same NTA token, improving registration flexibility</li>
<li>Users can now add API specs via URL reference in target settings, allowing the scanner to pull specs at runtime from targets not accessible to Invicti cloud services (<a href="/overview-of-scanning-apis#use-internal-url-references-for-api-specifications">Read more</a>)</li>
<li>NTA now automatically shuts down after multiple failed connection attempts to Invicti Platform (<a href="/nta-troubleshooting#authorization-failures">Read more</a>)</li>
<li>Dark mode is now available</li>
<li>Added preview capability for REST API specifications (OpenAPI, Swagger, RAML) after uploading (<a href="/ip/scan-rest-apis#preview-api-specification-operations">Read more</a>)</li>
<li>WAFs detected by DAST scanner are reported in the Scan activity log</li>
<li>Auto-scalable agents (<a href="/install-autoscaling-agent-k8s">Read more</a>)</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Improved user experience when creating API Discovery targets and starting scans</li>
<li>Addressed design inconsistencies for API discovery and API catalog pages</li>
<li>Improved API reconstruction speed from network traffic in NTA</li>
<li>NTA Helm deployments now automatically pull the most recent version, with older versions available upon request</li>
<li>Minor usability improvements across the app</li>
<li>API catalog now displays additional target details when clicking on a row (<a href="/ip/api-catalog-overview#api-details-drawer">Read more</a>)</li>
<li>SCIM swagger is now available among API specifications (<a href="/scim-provisioning-overview">Read more</a>)</li>
<li>Forms containing the <code>inv-ignore</code> CSS class are now excluded from DAST scanner testing</li>
<li>Scan duration calculation now includes scan pause time for more accurate reporting</li>
<li>Added pagination, sorting, and filtering capabilities to the PCI ASV scans page</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20251120]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20251120</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20251120</guid>
            <pubDate>Thu, 20 Nov 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>Added a bulk action for retesting vulnerabilities (<a href="/retest-vulnerabilities">Read more</a>)</li>
<li>Updated visibility of items in API discovery to show only unlinked API specs (<a href="/api-discovery-overview">Read more</a>)</li>
<li>Implemented API information export capability for API discovery and API catalog</li>
<li>Updated quick links to documentation and support in User profile</li>
<li>Implemented hostname variation handling during web crawling to ensure links with different subdomain formats are considered within the same scope</li>
<li>Implemented an upgrade process for NTA that preserves previous reconstruction context and avoids duplicate findings</li>
<li>Updated Docker Compose instructions to ensure the latest version of NTA is always used</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed a typo in user agent list</li>
<li>Fixed an issue related to the missing pagination</li>
<li>Fixed visibility of &quot;Vulnerability&quot; column on Trend Matrix page</li>
<li>Fixed an issue where filtering targets by agent type didn&#39;t work correctly</li>
<li>Implemented clear error messaging for app name length validation during creation</li>
<li>Fixed a filter label formatting in the UI</li>
<li>Fixed an issue related to incorrect time zone offset saving for users in GTM +1</li>
<li>Fixed an issue where the scan duration displayed an incorrect value despite no requests or progress</li>
<li>Fixed an issue with sorting of API operations in API discovery or catalog</li>
<li>Fixed an issue with the incorrect base URL displayed on the API Insights dashboard</li>
<li>Fixed an issue where audit logs for scans stopped by the system incorrectly displayed the user as the one who initiated the action</li>
<li>Fixed an issue with uploading large files via the API</li>
<li>Fixed an issue where the the count of vulnerabilites in the scan summary tab is less than actually detected</li>
<li>Unified pagination options in Automations</li>
<li>Unified pagination options in Integrations</li>
<li>Enforced SSO login for users with TOTP configured when organization SSO is enabled</li>
<li>Updated the design of License page</li>
<li>Fixed an issue where special characters could be used in the name fields</li>
<li>Fixed an incompatibility issue with uploading multipart form data via the API hub Swagger page</li>
<li>Fixed an issue where custom roles weren&#39;t updated after changing permission scope</li>
<li>Fixed counting of total open vulnerabilities in API Insights dashboard</li>
<li>Fixed visibility issues on internal scanning agent list</li>
<li>Fixed categorization issue of Audit log export</li>
<li>Improved data display in Audit log</li>
<li>Added proof of exploit information in the vulnerability drawer for IAST-enabled scans</li>
<li>Implemented pagination in API discovery and API catalog</li>
<li>Added scan end timestamp information to the automated email sent upon scan completion</li>
<li>Fixed displayed information on failed logins in Audit log</li>
<li>Fixed an issue where the source type returned by GraphQL didn&#39;t match the UI display for API targets</li>
<li>Extra validation now prevents creating sample issue when mandatory fields are incomplete</li>
<li>Fixed a loading delay issue on the User/Team creation and editing pages</li>
<li>Corrected the user status logic to ensure that enabled users aren&#39;t incorrectly marked as invite expired, aligning with the intended behavior</li>
<li>Resolved an issue related to username input handling on the login page</li>
<li>Fixed UI inconsistencies in the Settings - Automations input for domain entries</li>
<li>Added more detailed information about export configurations in audit log activity</li>
<li>Fixed &quot;Automations&quot; button to navigate correctly after a license upgrade</li>
<li>Addressed the UI and messaging issues on the forgot password page</li>
<li>Added forward and back navigation buttons to the role drawer for easier navigation</li>
<li>Improved performance by speeding up loading times when creating and editing user groups</li>
<li>Issue trackers now correctly show the respective icons in Automations overview</li>
<li>Better usability when working with email field in Automations</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20251106]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20251106</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20251106</guid>
            <pubDate>Thu, 06 Nov 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Added a &quot;Fixed (Unconfirmed)&quot; status to better reflect the status of a vulnerability</li>
<li>Implemented toggle in Settings to turn on/off the automatic retest of a vulnerability after selecting &quot;Fixed (Unconfirmed)&quot; status (<a href="/scanning-settings">Read more</a>)</li>
<li>Retesting a &quot;Fixed (Unconfirmed)&quot; vulnerability automatically sets the status to &quot;Fixed&quot; or &quot;Rediscovered&quot; (<a href="/retest-vulnerabilities">Read more</a>)</li>
<li>Added Sensorless API discovery (<a href="/sensorless-api-discovery-overview">Read more</a>)</li>
<li>Scan debug logs are available for download after a scan finishes (<a href="/download-scan-logs">Read more</a>)</li>
<li>User provisioning with SCIM is now supported for Invicti Ultimate users</li>
<li>Added an ability to filter the user list by user creation method (manually created vs. auto-provisioned) when auto-provisioning is available</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Added an ability to use custom cookies during DAST scans when using the LSR</li>
<li>API Discovery now clearly shows hostname where API specs have been identified</li>
<li>Token used by Network Traffic Analyzer (NTA) now has extended expiration date to support longer offline periods</li>
<li>Improved sitemap parsing to handle entries with multiple comma-delimited URLs within a single entry</li>
<li>Implemented filtering and sorting options for number of operations, discovered and last updated date in API discovery (<a href="/api-discovery-overview#view-discovered-apis">Read more</a>)</li>
<li>Implemented the display of PCI compliance status on the PCI scans list</li>
<li>Updated Chromium to <code>141.0.7390.122</code></li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue that prevented users from changing column order on selected list views</li>
<li>Fixed an issue where GetAssetById didn&#39;t return correct asset detail</li>
<li>Improved handling of whitespaces in the Target URL field during target creation (<a href="https://docs.invicti.com/ip/add-target#:~:text=Enter%20a%20name%20and%20the%20URL%20of%20the%20target.%20The%20URL%20mustn%27t%20contain%20any%20whitespace%20or%20spaces%2C%20as%20this%20is%20going%20to%20cause%20a%20warning%20message%20to%20appear.%20If%20you%20add%20a%20space%20before%20or%20after%20the%20URL%2C%20it%20is%20going%20to%20be%20automatically%20removed.">Read more</a>)</li>
<li>MTTR now shows &quot;-&quot; instead of &quot;0&quot; when there is no data</li>
<li>Fixed a navigation issue in &quot;Licensed FQDN&#39;s used&quot; list</li>
<li>Fixed an issue where the user can&#39;t change the start date for scheduled scans</li>
<li>Fixed an issue where the site structure isn&#39;t available for scans aborted by the DAST scanner due to network errors</li>
<li>Fixed an issue where the Project filter by Threat severity displays incorrect results</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20251023]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20251023</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20251023</guid>
            <pubDate>Thu, 23 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Implemented improvements to ensure the coordinator receives a heartbeat signal during the archiving process to prevent scan abortion</li>
<li>Added an ability to copy custom scan profiles</li>
<li>Updated requirements for the Internal Agent to specify CPU, RAM, and disk space</li>
<li>Added logs compression while the scanner is running</li>
<li>Updated PCI activation request emails to include a masked license key</li>
<li>Implemented new Engine-based Zero-Config API discovery service</li>
<li>Updated the design of the grid</li>
<li>Added information about discovered or reconstructed APIs in the Scan details page</li>
<li>Improved navigation to currently running scan from the Targets page</li>
<li>The Executive and API Insights dashboards now include Rediscovered vulnerabilities in the total open counts</li>
<li>Implemented filtering, sorting, and pagination features for PCI scans</li>
<li>Increased URL length limit from 1024 to 2048 characters</li>
<li>Implemented API-only scan capability to improve scan speed and efficiency</li>
<li>Implemented automatic screenshots when the automated login by the DAST scanner fails; screenshots are included in the scan logs</li>
<li>Added an updates panel to the Application dashboard. This panel displays last scanned status and tags. Additionally, the Vulnerabilities by scan type widget now shows the container count</li>
<li>Implemented filtering out third-party APIs during web application scans to improve API discovery accuracy</li>
<li>Reconstructed REST API specifications are now displayed in the API Discovery view</li>
<li>Added Vulnerability ID column to the Vulnerabilities page table</li>
<li>Updated the NIST SO 800-53 report to the latest template Rev5</li>
<li>Disabled the retest button during a retest scan to prevent multiple concurrent scans for the same vulnerability</li>
<li>The Settings page has a refreshed look and updated design for improved usability</li>
<li>Implemented a new automation feature to automatically email a specified scan report upon scan completion</li>
<li>The Audit Log now records changes made to vulnerabilities</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue where reports generated by the Vulnerabilities page didn&#39;t start</li>
<li>Fixed an issue where scans remained stuck in the &quot;starting&quot; status before their failure</li>
<li>Fixed an issue where PCI scan activities weren&#39;t shown in UI</li>
<li>Fixed the “List of URLs / Generic File (.txt/.*)” option to allow uploading files other than .txt</li>
<li>Fixed the deactivated toggle state for Discovery AI settings</li>
<li>Fixed an issue where the API Discovery remote target filter wasn&#39;t functioning correctly</li>
<li>Fixed an issue that prevented PCI scans from initiating when an internal agent was inactive</li>
<li>Fixed update logic for IAST sensor token</li>
<li>Restricted non-HTTP and non-HTTPS protocols in script initiated DeepScan sessions</li>
<li>Fixed an issue preventing users without an IAST license from saving target configurations</li>
<li>Scan profiles now correctly default to a preset when the previously assigned profile is deleted</li>
<li>Fixed a crash issue during scan</li>
<li>Fixed an issue where page navigation and data retrieval in &quot;Licensed FQDNs used&quot; weren&#39;t working correctly</li>
<li>Resolved an issue preventing users from editing scan schedules and corrected the incorrect display of scans on the Scan Scheduled page</li>
<li>Discovery Configuration navigation now correctly highlights the section you are currently in</li>
<li>Fixed an issue where the &quot;HTTP Authentication required&quot; message was shown incorrectly</li>
<li>Fixed a missing vulnerability on <a href="http://rest.vulnweb.com/">http://rest.vulnweb.com/</a></li>
<li>Resolved an issue where Browser Context creation starts failing after some time</li>
<li>Fixed an issue where Apigee APIM connection details couldn&#39;t be edited after being saved and authenticated</li>
<li>Queued scans are now displayed correctly</li>
<li>Fixed an issue where API-SEC permissions were incorrectly enabled for Essentials users</li>
<li>Updated vulnerability checks to include the new SQL injection in aspnet.testsparker.com</li>
<li>Prevented Ephemeral Target resuming scan from the UI when excluded hours are encountered</li>
<li>Fixed an issue where Filtering Targets on Scan Status duplicates some targets</li>
<li>The flow for LSR with OTP no longer requires an additional step to insert the OTP value</li>
<li>Fixed an issue where the Filter dropdown doesn&#39;t populate after reset</li>
<li>Fixed client certificate handling to prevent scans from failing due to certificate-related issues</li>
<li>Fixed an issue where logging in via SSO doesn&#39;t work when the user has TOTP/MFA enabled</li>
<li>Fixed an issue where the Project filter by Threat severity displays incorrect results</li>
<li>Fixed filtering capability and labeling of the &quot;Remote Target&quot; filter in the API catalog and discovery list</li>
<li>Fixed an issue where Hidden APIs become visible when filtering data</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20251009]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20251009</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20251009</guid>
            <pubDate>Thu, 09 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<h4>Improvements</h4>
<ul>
<li>API now supports filtering scan results by tags</li>
<li>Clicking on a target URL now opens the target details drawer</li>
<li>Added a button to request enabling PCI ASV scans directly in the product via email if the user has Professional/Ultimate license</li>
<li>Updated the notification instructing users to use Standalone LSR for targets that use internal scan agents</li>
<li>OTP tokens are now accessible for authorization scripts</li>
<li>Engine HTTP stats for API scans now include the number of 2xx status codes</li>
<li>Added the option to configure company details for the PCI ASV Report</li>
<li>Updated Inventory Endpoints in the API Hub</li>
<li>Added a filter to show only vulnerable APIs when navigating from the API dashboard to the API catalog</li>
<li>Added the ability for users to download debug scan logs</li>
<li>API Security is now available as an add-on for Essentials and Professional editions</li>
<li>Mapped security checks to their related found vulnerabilities</li>
<li>Only the Owner role can assign the Owner role and System and Subscription permissions</li>
<li>Added support for authentication scripts in the LSR</li>
<li>Added support for multiple BLRs with custom naming</li>
<li>Added a notification to inform the user when a scan is queued because of excluded hours</li>
<li>CSV import of Targets now allows specifying a username and password for form authentication</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed an issue where the Vulnerability Status column was missing from the Trend Matrix</li>
<li>Restored the missing Jira link on the Vulnerability page</li>
<li>Updated the Engine to correctly mark API specs loaded via GraphQL Introspection as Crawled instead of Imported</li>
<li>Fixed performance issues caused by DeepScan Static Analysis leading to slow page loading</li>
<li>Corrected an error preventing users from saving Max Password Age values greater than 10 days</li>
<li>Fixed mismatch between Value and Description for Inactivity Timeout in Session and Lockout settings</li>
<li>Fixed a UI issue where a deleted target was still visible in the Allowed Hosts section</li>
<li>Fixed an issue where DeepScan wasn&#39;t detecting Logout links</li>
<li>Fixed an issue where the Pattern attribute wasn&#39;t sent to the Scanner-AI-Service</li>
<li>Fixed inconsistency in scan schedule start times between the schedule list and detail views</li>
<li>Corrected sorting by Vulnerabilities on the Collections page, which previously caused an error</li>
<li>Fixed an SSO exemption bypass issue on page load</li>
<li>Resolved timezone errors in scheduled scans</li>
<li>Fixed an incorrect empty state message on the Collections page</li>
<li>Fixed an issue where Apigee APIM configurations couldn&#39;t be edited after authentication</li>
<li>Fixed an issue where users integrating with Mulesoft were redirected to an outdated configuration page</li>
<li>Resolved Jira field mapping inconsistencies</li>
<li>Fixed a UI issue where the Environment dropdown disappeared when scrolling on the Add Multiple Targets page</li>
<li>Ensured all “Add API Source” buttons open the same configuration page</li>
<li>Fixed issue causing Administrators to see empty content on the Settings page</li>
<li>Resolved inconsistent behavior when deleting custom profiles</li>
<li>Fixed mismatch between API Vulnerability counts on the Dashboard and other pages</li>
<li>Fixed an issue where API Insights displayed vulnerabilities even with zero APIs in the Catalog</li>
<li>Aligned API Insights counts for open vulnerabilities and other dashboard metrics</li>
<li>Fixed AI-aided login issues on sites requiring YES input during authentication</li>
<li>Resolved issue preventing users from generating API keys under migrated accounts</li>
<li>Validated Inventory Service endpoints to confirm proper UserID handling when using M2M tokens</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20250925]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20250925</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20250925</guid>
            <pubDate>Thu, 25 Sep 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Mark vulnerability with API tag when it comes from API target only</li>
<li>Added &quot;view by a time range&quot; options to the Application Trend Matrix</li>
<li>Added a new API parameter to filter vulnerabilities by severity in the vulnerabilities endpoint</li>
<li>Added the details about an API operation to the drawer in the API catalog</li>
<li>Added ability to configure the max scan duration for each Target. This can be used to specific smaller scan limits for scan done as part of CI/CD</li>
<li>Crawled APIs found are shown only once in API discovery</li>
<li>Added Invicti API to the list of integrations</li>
<li>Added an option to create a scan schedule directly from the Target&#39;s drawer</li>
<li>Added records of Applications, Assets, Collections to the Audit Log</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Improved error handling of the API Reconstructor to allow retries for failed uploads</li>
<li>Updated max API spec file size limit to 20&nbsp;MB when uploaded via target settings</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Fixed API specification duplication</li>
<li>Fixed filtering for Invicti NAD in API Discovery</li>
<li>Fixed an issue where automations created multiple issues out of one vulnerability</li>
<li>Fixed an issue where hidden APIs were counted in the API dashboard</li>
<li>Fixed an issue where exporting targets to JSON/CSV file returned empty files</li>
<li>Target URL in the Most Vulnerable APIs list links to API list</li>
<li>Added icons to Most recent discovered APIs based on the source type</li>
<li>Fixed incorrect count of operations in the API dashboard</li>
<li>Fixed count of Total APIs in API dashboard to reflect only APIs in the API catalog</li>
<li>Fixed the visibility of Web Discovery for an Essentials package user</li>
<li>Fixed the visibility of API security features for an Essentials package user</li>
<li>Fixed the order of buttons for Website discovery and API discovery</li>
<li>Fixed the order of the scan activity logs for scans with Allowed Host</li>
<li>Fixed dashboard charts not showing information without DAST targets added</li>
<li>Fixed filtering of multiple values for a single filter type</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20250911]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20250911</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20250911</guid>
            <pubDate>Thu, 11 Sep 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Added Vulnerabilities widgets to the Target Trend Matrix</li>
<li>The User Agent string is now displayed in Scan Configuration settings for each Target</li>
<li>Updated the scanner error message for status code 429 (Too Many Requests)</li>
<li>Added display of Mean Time to Remediate grouped by severity and indicated vulnerabilities exceeding MTTR</li>
<li>The Vulnerability drawer is now accessible in the Trend Matrix</li>
<li>Added the ability to export the Trend Matrix to CSV</li>
<li>Added filtering options for the Trend Matrix</li>
<li>Introduced the Trend Matrix for Applications</li>
<li>Improved the display of scan duration in reports</li>
<li>Added a custom User Agent option in Scan Configuration for Targets</li>
<li>FQDN utilization is now displayed in the side menu</li>
<li>Implemented automatic DAST scans in the GitHub Actions CI/CD pipeline</li>
</ul>
<h4>Improvements</h4>
<ul>
<li>Scan Profiles are now required for CI/CD integrations</li>
</ul>
<h4>Resolved issues</h4>
<ul>
<li>Resolved an issue that prevented manually entered sensor secrets from being saved</li>
<li>Enhanced scan summaries to provide clearer explanations for aborted scans</li>
<li>Resolved multiple issues related to HTTP/2 and LSR processing</li>
<li>Resolved handling of aborted scans in the command-line tool</li>
<li>Resolved an issue with restricted HTTP methods to ensure scan script requests are properly blocked</li>
<li>Resolved an issue with Jira bi-directional sync to ensure status updates are accurately reflected</li>
<li>Resolved an issue where scan progress displayed 100% without matching the actual scanner status</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20250828]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20250828</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20250828</guid>
            <pubDate>Thu, 28 Aug 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Scanning stops automatically when a 429 status is received without a retry-after header</li>
<li>Implemented Trend Matrix for DAST Targets</li>
<li>AI-Aided Login automatically regenerates invalid reused LSR files</li>
<li>Added support for tracking session tokens in URL Parameters for LSR recorder</li>
<li>DeepScan now scans all path fragments discovered in locations for potential vulnerabilities</li>
<li>Added a filter on the Vulnerabilities page to show vulnerabilities found on APIs</li>
<li>Added support in AI-Aided Login for saving AI-generated LSR files</li>
<li>Improved Agents Page with an updated design for better navigation and readability</li>
<li>Added the Technologies tab to the Application dashboard</li>
<li>Added user provisioning with SCIM 2.0 for Teams</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20250814]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20250814</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20250814</guid>
            <pubDate>Thu, 14 Aug 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Added the ability to restrict HTTP methods for a DAST scans on a Target</li>
<li>Added &quot;Export to file&quot; bulk action in Projects</li>
<li>Added &quot;Sync vulnerabilities&quot; bulk action in Projects</li>
<li>Added &quot;Last updated&quot; per SAST source in Projects</li>
<li>Added &quot;Export to file&quot; action in Projects</li>
<li>Added &quot;Sync vulnerabilities&quot; action in Projects</li>
<li>Added handling of custom namespaces in specifications for WSDL imports</li>
<li>Added NTA Standalone mode</li>
<li>Added details about an API operation to API catalog</li>
<li>Added &quot;Scan comparison&quot; feature to Past scans tab</li>
<li>Added a scan message when AI-aided login is used</li>
<li>Implemented automation to push vulnerabilities into issue trackers every time they are found, creating new or updating existing work items if needed</li>
<li>Added vulnerability assignment to a specific user</li>
<li>Implemented standard and compliance reports for Application consolidating all SAST asset vulnerabilities for a comprehensive application security overview</li>
<li>Added &quot;Most vulnerable technologies&quot; list to the Application dashboard</li>
<li>Added filtering by application, asset, and environment to the Vulnerabilities page</li>
<li>Added information on the status and version of the installed NTA to the API sources section in Discovery Configuration</li>
</ul>
<hr>
]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Release 20250730]]></title>
            <link>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#release-20250730</link>
            <guid>https://docs.invicti.com/ip/invicti-platform-on-demand-release-notes#20250730</guid>
            <pubDate>Wed, 30 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[New features, new security checks, improvements, and fixed issues introduced in the Invicti Platform on-demand across recent releases.]]></description>
            <content:encoded><![CDATA[<h4>New features</h4>
<ul>
<li>Enhanced DAST scanner with improved performance and vulnerability detection capabilities</li>
<li>Fully redesigned user interface and experience</li>
<li>New Applications feature allows to group related targets under logical application structures</li>
<li>AI-powered web form auto-completion for DAST scans <a href="https://www.invicti.com/blog/web-security/how-ai-enhances-dast-on-invicti-platform/">(Read more)</a></li>
<li>AI-powered authentication handling for DAST scans</li>
<li>Dynamic targets for integration into CI/CD pipelines <a href="/scan-dynamic-url-target">(Read more)</a></li>
<li>Detection of IDOR (Insecure Direct Object Reference) and BOLA (Broken Object Level Authorization) vulnerabilities in APIs <a href="/category/access-control-testing">(Read more)</a></li>
<li>Improved API analysis through stateful scanning capabilities</li>
<li>Concurrent scan support for internal scanning agents</li>
<li>Docker-based internal scanning agents</li>
<li>Simplified Packages</li>
<li>LLM vulnerability detection <a href="/llm-based-app-vulnerability-testing">(Read more about LLM-based app vulnerability testing</a>, <a href="/llm-based-app-vulnerability-testing#how-to-configure-an-llm-scan">how to configure LLM-scans</a>, and <a href="/llm-scan-verification">how to verify LLM was scaned during a scan</a>. LLM scanning includes:<ul>
<li>LLM Command Injection</li>
<li>LLM-enabled Server-side Request Forgery (SSRF)</li>
<li>LLM Insecure Output Handling</li>
<li>Tool Usage Exposure</li>
<li>Prompt Injection</li>
<li>System Prompt Leakage</li>
<li>LLM Fingerprinting <a href="https://www.invicti.com/blog/security-labs/invicti-platform-launch-research-update/#:~:text=Attacking%20LLM%20Applications">(Read more)</a></li>
</ul>
</li>
</ul>
<hr>
]]></content:encoded>
        </item>
    </channel>
</rss>